EN
56.571 CVE seguite
773 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia

CVE Tracker

56.571 CVE

Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.

CVE Tracker
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordinato dal più basso
CVE-2026-64912 HIGH 7.8 microsoft 365_apps Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. 0,3%
CVE-2026-64911 HIGH 7.8 microsoft 365_apps Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally. 0,3%
CVE-2026-64910 HIGH 7.8 microsoft 365_apps Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally. 0,3%
CVE-2026-64909 HIGH 7.8 microsoft 365_apps Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally. 0,3%
CVE-2026-64908 HIGH 7.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. 0,3%
CVE-2026-64907 HIGH 7.8 microsoft 365_apps Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0,3%
CVE-2026-64906 HIGH 7.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. 0,3%
CVE-2026-64905 HIGH 7.8 microsoft 365_apps Buffer over-read in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0,3%
CVE-2026-64904 HIGH 7.8 microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. 0,3%
CVE-2026-64903 HIGH 7.8 microsoft 365_apps Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally. 0,3%
CVE-2026-64902 MED 4.6 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. 0,4%
CVE-2026-64901 HIGH 8.8 microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 1,9%
CVE-2026-64900 HIGH 7.3 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. 0,4%
CVE-2026-64899 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. 0,3%
CVE-2026-64898 HIGH 7.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. 0,3%
CVE-2026-64897 MED 4.6 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. 0,4%
CVE-2026-64881 HIGH 8.8 tenable security_center The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system command execution. This input validation failure enables command injection when chained with a related vulnerability. 1,4%
CVE-2026-64880 HIGH 7.1 tenable security_center Unsanitized user-supplied input in report filtering parameters is concatenated directly into SQL queries without proper escaping or parameterized queries, enabling blind SQL injection and unauthorized database read access. 0,2%
CVE-2026-64879 CRIT 9.9 tenable security_center A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell metacharacters and achieve command injection via the audit file upload functionality. 2,6%
CVE-2026-64878 CRIT 9.9 tenable security_center Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling, resulting in remote code execution as a low-privileged OS user via the Analysis REST endpoint. 0,5%
CVE-2026-64877 HIGH 8.4 tenable security_center An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance database. 0,2%
CVE-2026-64640 MED 6.5 apache polaris Apache Polaris did not consistently validate storage locations supplied during table and view registration. An authenticated principal with permission to register a table or view could, depending on the affected release and registration path, cause Polaris to 0,4%
CVE-2026-64609 CRIT 9.1 apache fory Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-band zero-copy deserialization is used, readAlignedVarUint() can read beyond the bounds of the underlying buffer. Out-of-band zero-copy deserialization is an opt-in feature; applications that d 0,5%
CVE-2026-64608 CRIT 9.8 apache fory Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compatible mode, the field-skip paths do not correctly validate the declared field types against the actual data, so input with an inconsistent s 0,5%
CVE-2026-64607 MED 5.3 apache httpclient HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header value in the response message. Please note this defect does not a 0,4%